44 USC 3553 - Authority and Functions of the Director of OMB + the CISA Director. OMB DIRECTOR AUTHORITY: (a) overseeing agency information security policies + practices; (b) requiring agencies + contractors to identify + provide information security protections commensurate with the risk + magnitude of harm; (c) coordinating the development of standards + guidelines + with NIST + CNSS; (d) overseeing AGENCY COMPLIANCE with the requirements of this subchapter; (e) reviewing + approving + disapproving (within the OMB process) at least annually + the information security activities of agencies including the budget for information security; (f) coordinating Federal information security policy with related information resources management policies including the CLOUD-FIRST + SHARED SERVICES policies. CISA DIRECTOR AUTHORITY (transferred from DHS NPPD by the Cybersecurity and Infrastructure Security Agency Act of 2018): (a) operating the Federal information security incident center under Section 3556; (b) providing technical assistance + support to agencies; (c) issuing BINDING OPERATIONAL DIRECTIVES (BODs) - mandatory + compliance-required directives for federal civilian executive-branch agencies; (d) maintaining the KEV (Known Exploited Vulnerabilities) Catalog (BOD 22-01); (e) maintaining the National Cybersecurity Protection System (NCPS / EINSTEIN); (f) coordinating with the National Cyber Director (NCD) + the OMB. KEY BODs: BOD 22-01 KEV Catalog + remediation timelines (15 days from inclusion); BOD 23-01 Asset Visibility + Vulnerability Detection (agency network discovery); BOD 23-02 Internet-Accessible Networking Devices; BOD 25-01 (pending) Cloud Security; BOD 18-02 SecOps continuity. AGENCIES must implement BODs within statutory timelines; non-compliance triggers OMB + congressional oversight + potential funding action.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.